Cursor AI-generated code contains security flaw allowing privilege escalation
Code generated by AI coding assistants like Cursor and Claude Code for user profile update routes contains a mass assignment vulnerability. The generated code often accepts the entire request body directly into a database update function. An authenticated user can exploit this by adding fields like 'role: admin' to a request, which the database then accepts. The vulnerability, identified as CWE-915, allows unauthorized modification of sensitive user attributes, including account privileges and related data.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in